Privacy Policy
Last updated 3 September 2026
The short version
- Oath does not track your screen time. It reads which app is in front of you, because that is the only way it can block one, and it keeps no record of your screen time. It does not hold Android's Usage Access permission at all.
- What does leave your phone is what an Oath needs to work: your name and email from Google Sign-In, the rules you agree with your partner, and a record of when a rule was broken.
- We do not sell your data, and Oath contains no advertising or analytics trackers. When the app breaks, we get a crash report telling us what went wrong and on what kind of phone, never what you were doing.
- Your partner sees less than you might expect. They are not told when you break a rule. Details in "What your partner can see".
Our contact details
Name: Way Studio
E-mail: waystudio.apps@gmail.com
Way Studio is the name Immanuel Rajiv, an independent developer in the United Kingdom, makes Oath under. For the purposes of UK data protection law he is the "controller" of the personal data described in this policy. It covers the Oath Android app (package app.getoath.android) and this website.
Oath is published through a Google Play developer account held by a separate company. Google is the seller. That company does not decide how the personal data in this policy is used.
As an independent developer he is not required to appoint a Data Protection Officer, so please send all data protection queries to the address above.
The type of personal information we collect
What stays on your phone only
The following is stored in a database on your device and is never transmitted to us or anyone else. If you uninstall Oath, it is deleted with the app.
- Timer sessions: the sessions you run and the apps you chose to block.
- Session rule counts: if a rule gives you a set number of sessions in an app, the number you have started today and when the current one ends.
- Your settings and preferences.
Oath used to record your app usage on this device, for screen-time charts it no longer shows. That collection was removed in September 2026, along with the Usage Access permission behind it. Oath does not ask for that permission and cannot read your usage figures.
What is sent to our servers
Oath uses Google Firebase to let two people share an Oath across two phones. Only the data below is sent.
| Data | Why it is needed | Our lawful basis |
|---|---|---|
| Google account details | Your display name, email address, profile photo URL, and a Google-issued user ID. Used to sign you in and to show your partner who they are paired with. | (b) Contract |
| Notification token | A Firebase Cloud Messaging token identifying your device, so your partner's phone can reach yours with a notification. | (a) Consent |
| Oath and rule content | The rules you and your partner agree: the rule name, the time limits and windows, and the package names of the apps you name in a rule (for example com.instagram.android). Both partners must see the same rules, so they are stored centrally. |
(b) Contract |
| Breach records | When a rule was broken, which rule, the app that triggered it, and how it was resolved. Also any note you type when requesting a key, and any note your partner types when declining. | (b) Contract |
| Partner linkage | Which two accounts are joined in an Oath, and the short invite code used to join. | (b) Contract |
| Subscription status | Whether your account is in a trial or has an active subscription, verified with Google Play. We never see your card details; Google handles payment. | (b) Contract |
| Crash reports | When Oath crashes, or hits an error it can recover from, Firebase sends us the technical details: what went wrong, where in the code, and your device model and Android version. We attach no name, email or account ID. Firebase attaches two identifiers of its own so it can count how many people one bug affected. It keeps all of it for 90 days and then deletes it. Test builds send nothing. | (f) Legitimate interests |
| App integrity checks | A Google Play Integrity token confirming the request came from a genuine, unmodified copy of Oath. This stops a tampered app forging a subscription or writing to someone else's Oath. | (f) Legitimate interests |
There are no usage figures for us to receive. What a rule you write does name is the apps it governs, and a breach record names the app that triggered it. If you would rather an app was not named on our servers, keep it out of a shared rule.
How we get your personal information and why we collect it
Most of the personal information we process is provided to us directly by you, when you sign in with Google, when you write a rule, and when you send a note to your partner. We also receive information indirectly from two sources: Google Sign-In gives us your name, email address and profile photo URL when you authorise it, and Google Play tells us whether your subscription is active.
We use that information to create and run your account, to keep your Oath in step across two phones, to let your partner grant you a key, to send the notifications described below, and to confirm you are entitled to the paid features.
The Accessibility Service
Oath cannot block an app without Android's Accessibility Service, so we ask you to turn it on. It is a powerful permission, so here is the whole of what Oath does with it.
- Oath uses the service for one purpose: to detect which app has just come to the foreground, so it can show a blocking screen when that app is covered by an active rule or Timer session.
- Oath does not read, record, or transmit the contents of your screen, what you type, your messages, your passwords, or anything inside other apps.
- The foreground app name is evaluated on your device and is not sent anywhere, except where a package name forms part of a rule or a breach record as described above.
- You can turn the service off at any time in Android Settings. Blocking then stops working.
Oath can see which apps on your device have an icon in your launcher, so you can choose apps when writing a rule. This is a declaration in the app rather than a permission you grant, and Android limits it to apps that can be opened. The list is used on your device to draw the picker and is not uploaded.
Our lawful bases
The table above names the lawful basis for each kind of data. Under the UK GDPR, those bases are:
- (a) Your consent. This covers the Accessibility Service and notifications. You are able to remove your consent at any time. Each one can be withdrawn in your Android settings, and you can also contact us at waystudio.apps@gmail.com.
- (b) We have a contractual obligation. This covers your account details, Oath and rule content, breach records, and subscription status. Without these, the service you signed up for cannot function.
- (f) We have a legitimate interest. This covers keeping the service secure and preventing abuse, including Google Play Integrity checks that confirm requests come from a genuine copy of the app, and the crash reports that tell us why the app failed.
What your partner can see
An Oath shows your partner less than most people expect. They can see:
- Your display name and profile photo.
- The rules you both agreed, and any change either of you proposes.
- A shared history of breaches on the Oath, and whether each was resolved.
- Any note you write when you ask them for a key.
Your partner is not sent a notification when you break a rule. Breaches are quiet by default. They are notified only when you ask them for a key, when you use a hammer to release yourself, when they decline a request, and when the Oath is paused, revived, or dissolved.
Your partner never sees your Timer sessions, or any app you have not named in a shared rule.
Who we share your information with
We use a small number of processors, and we do not sell data to anyone.
- Google Firebase (Google Ireland Limited), for authentication, database, notifications, crash reporting, and app integrity checks. Our database is hosted in Google's
eur3European multi-region, which stores data in Belgium and the Netherlands. Our server functions run in Belgium. - Google Play Billing: subscriptions and payment. Google is the seller and handles your payment details directly. See Google's own privacy policy for how they process them.
- Google Fonts: this website loads its typefaces from Google's font service, which means Google receives your IP address when a page loads. The app does not do this.
We may also disclose data where the law requires it, or to protect our rights or someone's safety.
Cookies. This website sets no cookies and contains no analytics or advertising trackers. Your visit is not tracked. The Oath app sets no cookies either.
How we store your personal information
Your information is stored with Google Firebase, in the eur3 European multi-region (Belgium and the Netherlands). Access to our database is governed by server-side security rules that restrict every record to the people party to it, and sensitive operations run as server functions rather than being trusted to the app. Subscription entitlements are verified on our server, not on your phone. Requests are checked with Google Play Integrity to confirm they come from a genuine, unmodified copy of Oath.
Our database region is in the EEA. Google, as our processor, may transfer or access data outside the UK and EEA in the course of running its infrastructure and support. Where that happens, transfers are covered by the UK International Data Transfer Addendum or Standard Contractual Clauses.
We keep your information for the following periods, after which it is deleted from our database:
- Account details: until you delete your account.
- Oath, rule, and breach records: for as long as the Oath exists. When an Oath is dissolved it is archived to your history and your partner's history, because it is a shared record that belongs to both of you. It is removed when either of you deletes your account, apart from one thing: your partner keeps a short marker saying the Oath ended and that you ended it, and that marker includes your display name. Their phone needs it to close the Oath and to lift any block it was still holding. It contains nothing else about you.
- Invite codes: deleted once the invite is accepted or the Oath ends.
- Notification tokens: replaced when Android reissues them, and removed when you delete your account.
- On-device data: kept until you clear the app's storage or uninstall it. This one is in your hands, not ours.
- Three records that outlive your account: kept for as long as they are needed, for the reasons set out in "What is left after you delete your account" below.
What is left after you delete your account
Deleting your account removes your profile, your Oath, your rules and your breach history from our database. Three small records stay behind. Each holds a date and a reference code. None holds your name, your email address, or anything you wrote.
The reference code is made from your Google account identity using a key we hold. Nobody outside can read it, but we can still match it to you, so these are not anonymous records and we treat them as your personal data.
- A record that your deletion finished, so a phone that was offline at the time can confirm later that the account is gone and stop applying rules for it.
- The date your free trial started, so that deleting an account and signing up again does not start a new free trial every time.
- Which Google account a subscription belongs to, so you can delete your Oath account and still keep the subscription you paid for.
None has a fixed end date. Each lasts as long as the job it does: the deletion record, while an offline phone could still be applying rules for the deleted account; the trial record, while we offer one free trial per person; the subscription record, while Google can still restore the subscription. A timer on any of them would undo it. An expired trial record hands the same person a new trial each time they delete their account.
No service can promise perfect security, and we do not. If a breach occurs that puts your rights at risk, we will tell you and the ICO as the law requires.
Automated decision-making
We do not make automated decisions about you that produce legal effects or similarly significant effects, and we do not profile you.
Oath does apply your own rules automatically: when an app you named goes past a limit you agreed, that app is locked without anyone reviewing it first. It affects only that app, on your own phone, and is not used to judge or score you.
Your data protection rights
Under data protection law, you have rights including:
- Your right of access — You have the right to ask us for copies of your personal information.
- Your right to rectification — You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Your right to erasure — You have the right to ask us to erase your personal information in certain circumstances.
- Your right to restriction of processing — You have the right to ask us to restrict the processing of your personal information in certain circumstances.
- Your right to object to processing — You have the right to object to the processing of your personal information in certain circumstances.
- Your right to data portability — You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
- Your right to withdraw consent — Where we rely on your consent, you have the right to withdraw it at any time.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at waystudio.apps@gmail.com if you wish to make a request.
To delete your account and the data attached to it, see Deleting your account.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at waystudio.apps@gmail.com. We would rather you told us first so we can put it right.
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO's address:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
Children
Oath is not designed for children and is not directed at them. You must be at least 18 to use it. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell you in the app before it takes effect.